While AI-Assisted Fraud Is Surging, Veriff Reports Old Methods Still Popular
While fraud continues to evolve (with AI playing its part), Veriff fraud platform lead, Ira Bondar-Mucci, said familiar methods still reign supreme. Veriff’s identity verification platform supports more than 3,000 businesses, including Western Union, Bumble, Blockchain, Stake, Instacart and AWS. Veriff’s 2026 Identity Fraud Report finds that e-commerce and financial services firms are the hardest hit sectors.
Injection attacks are the fastest-growing problem. During verification, fraudsters submit pre-made or edited content in place of a live selfie and ID photograph to bypass the camera. Using web platforms and photo editors, they can subtly alter identities at scale and apply them across industries. This is very common in fintech and BNPL.
“When looking holistically into all the fraud attacks, fraud factors that we are seeing at Veriff, it’s that mundane fraud that is still in the majority,” Bondar-Mucci said. “It’s the cheapest fraud for fraudsters to commit, so whenever they identify a small vulnerability in a system, they try to optimize their operations and use that specific vector many, many times before we stop them, and they need to figure out what’s next.”
Impersonation, multi-accounting and money mill fraud explained
Impersonation fraud occurs when a criminal alters physical or digital records to assume another’s identity. AI helps this by simplifying voice and image alterations. What took days previously now takes minutes, and it is done on a much larger scale. It accounts for more than 85% of all fraud.
Multi-accounting is often used in cryptocurrency and other sectors that offer bonuses. One actor creates multiple accounts to glean as many benefits as possible. These criminals often leave digital clues and pattern trails.
Bondar-Mucci said money mills can be tricky. Real people are recruited by fraudsters to willingly cede their identities. Once verified, they turn over the accounts.
Fraud stable, yet changing
Overall, fraud levels are consistently around 4%, but what makes up that 4% is in flux. Physical document fraud has plummeted in favor of digital methods. AI has greatly simplified this process. In 2025, digitally presented media was 300% more likely to be AI-generated or somehow altered than in 2024. While still a small percentage of overall fraud, AI-assisted fraud is surging.
Adversary-in-the-middle attacks, both physical and digital, are much rarer today. Physical attacks dropped by 34% last year to account for only 1.28% of attacks, while digital attacks dropped by 66%; they now account for only 0.02% of all fraudulent attempts. Some credit increased customer sophistication for part of the fall, but Veriff suggests AI reduces the need for these attacks at all.
Emulators, originally designed as software development testing tools, have been co-opted by criminals to mimic the behavior of legitimate devices and users. This capability allows fraudsters to manipulate apps, websites, and payment systems. It’s easily automated, and with the ability to appear as different devices, eminently scalable.
The best protection is a multi-layered approach including facial biometric identification, behavioral analytics, code auditing, vulnerability testing, machine learning algorithms, web application firewalls, IP and device fingerprinting, email analysis, and AI-driven algorithms.
E-commerce sites are popular fraud targets
In 2025, e-commerce platforms saw a net fraud rate of 19.2%, nearly five times the global average. E-commerce also saw 10 times the global average of authorized fraud, with gig economy, mobility, and ride-hailing platforms frequently targeted.
These platforms are largely unregulated and see trillions of dollars transacted every year. Bondar-Mucci said that the customer’s need for speed and low-friction onboarding make the sector a prime target; instant value, immediate payoff.
However, fraudsters must be careful, as they often replicate their strategies across platforms. With Veriff employing a database of behaviors detected at thousands of companies, it helps detect patterns.
Different fintech areas see different types of attacks. Crypto sites and lenders see more identity fraud. Trading and investment sites see more authorized fraud. Banks see plenty of both.
“On average, the total attempted fraud rate has increased by over 38% in the crypto sector year-on-year and by 9.6% in the payments sector, while the total attempted document fraud rate has increased by over 21% in the crypto sector,” Veriff’s report states.
Regional differences
North America
Net fraud rates were stable between 2024 and 2025, but 20% of all fraud was document fraud, much higher than anywhere else. Financial services departments were heavily targeted with fraudulent residence permits, where overall fraud rates for these documents were 18.6%.
The US payments sector entered high-risk territory following an 89% increase in the attempted fraud rate, driven by increased digital media use.
EU/UK
The annual mean fraud rate increased nearly 2.3X. Bondar-Mucci said companies face added regulatory and compliance requirements. This catches more previously unnoticed fraud. ID cards see a 13% attempted fraud rate, more than double passports’ 6%.
UK platforms saw 35% more fraudulent attempts.
Latam
Fraud was consistent from 2024 to 2025. Impersonation fraud was 86%, and document fraud 13%. Passports saw a 5.82% average 2025 fraud rate. On gambling sites, ID cards saw an 11.8% attempted fraud rate. Payments saw a 48% increase in fraudulent attempts; fintechs saw a 23.4% fraud surge.
Bondar-Mucci said Veriff tracks global activity in part by looking for mismatched fraud data.
“For example, if someone has submitted a document from the US, but we are seeing that the language that is installed on their mobile device or the IP address is coming from a different region, that’s a big red flag for us.”
How to fight AI-assisted fraud
Fraudsters will continue to seek new ways to use AI to deceive detection systems, and companies will leverage it in seeking to stop them. Bondar-Mucci said a multi-layered approach is mandatory.
“Apply everything that you have in your stack,” she said. “It is the biometric authentication; it is liveness verification. One of the important, important signals is the device information, because (some) media will pass biometric authentication, but it will not pass the device integrity checks.
“Device signals and network signals are not to be underestimated, because this will be the signal that tells us about the behavior of the end user interacting with the system. With deepfakes getting more and more realistic, we are getting fewer and fewer signals to work with.”
It also means that companies must protect vulnerabilities across the interaction lifecycle.
“We are seeing that this continuous trust is as important, because if today a good-looking account simulates some good behavior and completes some legitimate transactions, but then after they are off the radar, they can hit again and request some risky transactions,” Bondar-Mucci said. “If it goes under the radar, there is a big financial risk that the company will have to sustain.
“If the user is changing their data on their account, if they are requesting a transaction from a weird place, or it doesn’t look overall holistic with the with the with their account history, there are ways to create those on-demand verifications.”
Companies must also stop viewing fraud protection as a cost center and start from the mindset of catching bad actors while not punishing legitimate customers. Bondar-Mucci said a risk-based orchestration approach allows companies to design flows based on their risk appetites and the regulations they must follow.
Veriff’s consortium approach, where it accesses data from thousands of companies, helps protect customers.
“If we have seen them in the past when onboarding them to 10 banks, why should we scrutinize them when they are trying to get access to a new service when we already know that this is a trusted identity?” Bondar-Mucci asked. “This trust, it’s looking at the fraud from a different perspective, (it’s) allowing good users faster access while scrutinizing the flows and really making it complicated for fraudsters to proceed.
“This risk-based orchestration is the future.”
Â
